2026 CVE Vulnerabilities

49,039 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-10884HIGH8.3Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the r...
CVE-2026-10883HIGH8.8Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap co...
CVE-2026-10882HIGH8.8Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code vi...
CVE-2026-10873HIGH7.3A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats ...
CVE-2026-10872HIGH7.3A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/...
CVE-2026-11322HIGH7.1Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace bo...
CVE-2026-10871HIGH7.3A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of t...
CVE-2026-5066HIGH8.8A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/...
CVE-2026-10870HIGH7.3A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the comp...
CVE-2026-41522HIGH7.1Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior...
CVE-2026-41518HIGH7.6Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-41249HIGH8.2CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow ...
CVE-2026-41237HIGH8.6Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` whi...
CVE-2026-41236HIGH8.8Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned...
CVE-2026-41235HIGH8.6Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_she...
CVE-2026-41234HIGH7.6Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does n...
CVE-2026-40898HIGH7.5quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory...
CVE-2026-25551HIGH8.5Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-pri...
CVE-2026-10796HIGH7.5nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured No...
CVE-2026-49942HIGH7.3Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could ...
CVE-2026-49941HIGH7.5Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method t...
CVE-2026-46741HIGH7.5Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked fo...
CVE-2026-5228HIGH8.8Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing...
CVE-2026-44393HIGH7.4An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe...
CVE-2026-43985HIGH8.8Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now